Explore Cenitia’s compliance workflow and availability.Cenitia compliance workflow

How it works →
Cenitia
How it worksServicesLibraryGlossaryRegulationsToolsAbout
Reserve your spot
How it worksServicesLibraryGlossaryRegulationsToolsAbout

On this page

  • Conformity assessment A, B+C and H
  • Scope and exclusions
  • Evidence to keep with the product
  • Using Cenitia for this work
  • Review status
  • Primary references
← Library
reference·CRA·3 min read

CRA Annex III important products — Class I and Class II explained

An overview of CRA Class I and Class II assessment routes and scope checks. Classify the actual product using Annex III and the applicable technical descriptions.

By Cenitia · 22 June 2026 · Updated 5 October 2026

Classify by the product’s main functionality and the actual Annex III/IV category, using the technical descriptions in Implementing Regulation 2025/2392. A generic IoT label, an embedded firewall component or a medical wearable description does not settle CRA class or scope.

Conformity assessment A, B+C and H

Annex VIII offers internal control (A), EU-type examination plus conformity to type (B+C), and full quality assurance (H). Standard products may use A. Important Class I A depends on Article 32(2) full coverage through applicable harmonised standards, common specifications or qualifying certification; otherwise B+C or H. Class II uses B+C or H under Article 32(3). Article 32(5) allows qualifying important free/open-source software with public technical documentation to use A. Critical products require assessment of Article 8 certification conditions; absent the mandated suitable scheme conditions, Article 32(4) provides B+C or H. Classify the main product function against Annexes III/IV and implementing technical descriptions 2025/2392, not a component name alone.

Scope and exclusions

CRA concerns products with digital elements made available on the EU market whose intended or foreseeable use includes a direct or indirect logical or physical data connection. MDR/IVDR devices and other Article 2 exclusions require separate scope assessment. Assess manufacturer responsibility and the statutory remote-data-processing definition, not cloud dependence alone. Main product requirements apply from 11 December 2027; Article 14 reporting applies from 11 September 2026.

Evidence to keep with the product

Record the intended purpose, responsible economic operator, target market, first placing date and exact hardware/firmware configuration. For each applicable requirement, link the actual test or assessment record, dated standard/specification, scope and reviewer decision. Proposed controls and supplier marketing statements are not evidence that the final configuration has passed an assessment.

Separate an open question from a completed assessment. A report outside the laboratory's relevant scope, a different firmware build or an unverified exemption needs a reasoned decision before it supports a declaration. Keep original evidence and the issued declaration alongside any AI-assisted working draft.

Using Cenitia for this work

Cenitia assists with a limited regulatory catalogue and draft documents. The manufacturer must confirm applicability, actual applied specifications and completed assessment procedures. AI scores are quality signals, not a probability of conformity. Source monitoring raises a review prompt when validated source text changes; it does not automatically verify amendments, update the corpus or monitor every national rule and OJ standard edition. Public QR verification records issuance, not product certification.

Review status

This guide was substantively corrected by Cenitia on 2 October 2026 using the primary references below. It is an editorial summary, not an authoritative legal quotation or an independently signed expert opinion. Product-specific and licensed-standard questions remain subject to a real technical review.

Primary references

  • Primary source 1

FAQ

Frequently asked questions

  • Does an AI draft or QR verification prove conformity?+

    No. The manufacturer must establish scope and satisfy applicable requirements using actual evidence. QR verification records issuance, not product certification.

  • What information must be checked for this product?+

    Confirm intended use, role, market/date, final configuration, dated specifications, assessment route and evidence scope. Record unresolved questions and a real reviewer decision.

Continue reading

Related guides

  • tutorial

    Coordinated Vulnerability Disclosure Policy for Hardware Manufacturers

    Build a usable hardware vulnerability disclosure policy with intake owners, safe testing boundaries and a security.txt example.

    4 min read

  • reference

    CRA for existing products already on the EU market: the Article 69 transitional rules

    CRA Article 69 explained: grandfathering for products placed on the EU market before 11 December 2027, substantial modification test, Article 14 reporting carve-back.

    14 min read

  • comparison

    ISO/IEC 27001 vs CRA — when to certify both

    ISO/IEC 27001:2022 is an organisational ISMS standard; the EU Cyber Resilience Act is a product-level regulation. Where they overlap, where they don't, and why you need both.

    9 min read

  • tutorial

    CRA December 2027 readiness — scope, assessment and evidence checks

    Key checks before CRA main product obligations apply: legacy products and modifications, support and retention, assessment route, declaration and technical evidence.

    3 min read

Put this into practice

Free tools & references

  • CRA Readiness CheckerScore your product against the Cyber Resilience Act essential requirements.Open tool →
  • EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →

New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.

Explore Cenitia’s compliance workflow

Review the supported scope and workflow

← Back to Library

Cenitia

The EU compliance engine for hardware manufacturers. Cited drafts, electronic signing, regulation watching — all in one place.

A product of Inovasense s.r.o., Bratislava, Slovakia · Data hosted in Stockholm, EU

Site

  • How it works
  • Expert services & pricing
  • Library
  • Glossary
  • Regulations
  • By product type
  • Tools
  • About

Legal

  • Imprint
  • Privacy
  • Terms

© 2026 Inovasense s.r.o. · cenitia.com

Operated in Slovakia · Evidence, expert review and clear service scope